Privacy Policy
T. Stephan
Kookamp 40
46354 Südlohn
E-Mail: info@exoda.de
Phone: +49 171 3833568
Last updated: February 2026
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
T. Stephan
Kookamp 40
46354 Südlohn
E-Mail: info@exoda.de
Phone: +49 171 3833568
2. Overview of Processing
We process personal data of our users only to the extent necessary to provide the app "Exoda Engraving" and our services. Processing is based on the GDPR and the German Federal Data Protection Act (BDSG).
3. Data Collected
3.1 When Using the App
The following data is automatically collected when using the app:
- Device type and operating system
- App version
- Time of access
- Firebase installation ID (anonymous device identifier)
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the technical provision and security of the app).
3.2 During Engraving Configuration
The motifs, instructions, and generated engraving images you enter are processed for order fulfilment and stored in Firebase Storage.
Legal basis: Art. 6(1)(b) GDPR (contract performance).
3.3 During Ordering and Payment
For order processing and payment we process:
- E-mail address (if provided)
- Payment data (processed directly by Stripe, see Section 6)
- Order details (configured products, prices, order time)
Legal basis: Art. 6(1)(b) GDPR (contract performance).
3.4 Push Notifications
With your consent, we send you push notifications. For this purpose, a device-specific FCM token (Firebase Cloud Messaging) is stored.
Legal basis: Art. 6(1)(a) GDPR (consent). You can withdraw consent at any time in your device settings.
4. Data Storage and Deletion
(1) Order data is stored for the duration of legal retention obligations (generally 10 years pursuant to §§ 147 AO, 257 HGB — German fiscal and commercial law).
(2) Shopping basket data is stored only locally on your device and deleted when the app is uninstalled.
(3) Other personal data is deleted as soon as the purpose of processing ceases and no legal retention obligations apply.
5. Firebase (Google)
We use services of Google Firebase (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) for the following purposes:
- Firebase Core – App initialisation
- Cloud Firestore – Storage of article data and price configurations
- Firebase Storage – Storage of generated engraving images
- Cloud Functions – Server-side payment processing
- Firebase Messaging – Push notifications
Google processes data on servers within the European Union (EU/EEA). No transfer to third countries takes place.
Google's privacy policy: https://policies.google.com/privacy
6. Stripe (Payment Processing)
For payment processing we use Stripe Payments Europe, Ltd. (1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland).
The following data is transmitted directly to Stripe during payment:
- Payment data (credit card number, expiry date, CVC)
- Transaction amount and currency
- E-mail address (if provided)
- Device information for fraud prevention
We do not store credit card data ourselves. Payment data is processed directly by Stripe and transmitted in encrypted form. Stripe is PCI DSS Level 1 certified.
Legal basis: Art. 6(1)(b) GDPR (contract performance).
Stripe's privacy policy: https://stripe.com/privacy
7. OpenAI (AI Image Generation)
For generating engraving images, we use the API of OpenAI, L.L.C. (San Francisco, USA). Your text description (motif, instructions) and optionally a reference image are transmitted to OpenAI's servers.
OpenAI does not permanently store image data from API requests and does not use it for training.
Legal basis: Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(f) GDPR (legitimate interest in providing the AI-assisted service).
OpenAI's privacy policy: https://openai.com/policies/privacy-policy
8. Apple Pay & Google Pay
If you use Apple Pay or Google Pay as a payment method, your payment data is processed directly by Apple or Google. We do not have access to your full payment data.
9. Your Rights
Under the GDPR you have the following rights:
- Access to your stored data (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure of your data (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing (Art. 21 GDPR)
- Withdrawal of granted consent (Art. 7(3) GDPR)
To exercise your rights, please contact: info@exoda.de
10. Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority. The competent authority depends on your place of residence. A list of authorities can be found at: https://www.bfdi.bund.de/DE/Service/Anschriften/Laender/Laender-node.html
11. Changes to this Privacy Policy
We reserve the right to adapt this privacy policy as necessary to keep it in line with current legal requirements or to reflect changes to our services. The updated policy will apply to your next visit.